Oneleet logo
OneleetΒ·

Security Program Manager - Oneleet

About Oneleet

Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners.

Having just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry.

The Security Program Manager is part vCISO & part account manager. You will work with our customers from the start to assess their current security/compliance framework, provide guidance and recommendations for improvements, and work with clients to implement recommendations. You're passionate about security, and enjoy sharing your knowledge with not only our customers but your colleagues.

Key Responsibilities

  • Conduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives.
  • Provide guidance and recommendations for improving client security posture.
  • Develop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs.
  • Collaborate with clients to customize and refine the security program to match their specific use cases.
  • Communicate with clients and stakeholders to ensure smooth and efficient security program creation.
  • Liaise with auditors to ensure clients' security programs align with auditors' expectations.
  • Maintain expertise across a range of security frameworks, control types, and technologies including NIST, SOC2, ISO27001, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more.
  • Provide feedback to Oneleet's engineering team to inform development of integrations, solutions, and products that deliver on client needs.
  • Be highly technical, learn new technologies quickly, and translate security concepts into implementations.
  • Partner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations.

Requirements

Security/Compliance Experience

  • 4+ years in a role involving information security, compliance, or audit (security operations, GRC, vCISO, security advisory, IT/Compliance auditing, or a security-adjacent customer success/IT support role).
  • Working and broad knowledge of security best practices, major compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, PCI), and how controls map to real infrastructure and operations.

Account Management Experience

  • Technical Account Management experience, or client facing or stakeholder facing experience with strong project management instincts.
  • Ability to understand client infrastructure and map security controls to meet compliance goals and the bigger picture of holistic security and compliance.
  • Strong analytical skills to evaluate environments and determine appropriate safeguards.
  • Excellent verbal and written communication skills.
  • Self-driven with the ability to work independently, comfortable with ambiguity, and able to adapt approach client-by-client in a fast-moving startup environment.

Perks & Benefits

  • Comprehensive health & wellness benefits
  • 20 days PTO per year, plus 8 floating holidays
  • Remote work culture
  • Team off-sites in stunning places (Amsterdam, Italy, etc.)
  • Competitive compensation & equity

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Oneleet

Similar remote roles